Skip to content

Commit a5c64f2

Browse files
committed
Added Applaunch.yml
1 parent dcca4db commit a5c64f2

File tree

1 file changed

+36
-0
lines changed

1 file changed

+36
-0
lines changed

yml/OSBinaries/Applaunch.yml

Lines changed: 36 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,36 @@
1+
---
2+
Name: Applaunch.exe
3+
Description: ClickOnce partial-trust application launcher used by .NET. Can execute self-signed or untrusted ClickOnce applications without SmartScreen or standard AppLocker enforcement.
4+
Author: Nathan Sawyer
5+
Created: 2025-11-26
6+
Commands:
7+
- Command: >
8+
"C:\Windows\Microsoft.NET\Framework64\v4.0.30319\Applaunch.exe"
9+
/activate "{APPLICATION_URL}#{APPLICATION_METADATA}"
10+
Description: Launches a ClickOnce application via Applaunch.exe. Bypasses SmartScreen and default AppLocker rules when the application is published as partial trust.
11+
Usecase: Execute ClickOnce applications in environments where dfsvc.exe would normally enforce full-trust and SmartScreen checks. Can be abused as an AWL bypass in rare configurations.
12+
Category: AWL Bypass
13+
Privileges: User
14+
MitreID: T1127.002
15+
OperatingSystem: Windows Vista, Windows 7, Windows 8, Windows 8.1, Windows 10, Windows 11
16+
Tags:
17+
- Execute: ClickOnce
18+
- Execute: Local
19+
- Execute: InstalledApplication
20+
21+
Full_Path:
22+
- Path: C:\Windows\Microsoft.NET\Framework\v2.0.50727\Applaunch.exe
23+
- Path: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\Applaunch.exe
24+
- Path: C:\Windows\Microsoft.NET\Framework\v4.0.30319\Applaunch.exe
25+
- Path: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\Applaunch.exe
26+
27+
Detection:
28+
- IOC: Applaunch.exe rarely executes unless any ClickOnce partial trusted apps are used. Any use or invocation outside dfsvc.exe with `/activate` should be considered suspicious.
29+
30+
Resources:
31+
- Link: https://learn.microsoft.com/en-us/visualstudio/deployment/clickonce-security-and-deployment
32+
- Link: https://web.archive.org/web/20060913192623/http://blogs.msdn.com/shawnfa/archive/2005/11/30/498610.aspx
33+
- Link: https://nathan2.com/posts/applaunch
34+
35+
Acknowledgement:
36+
- Person: Nathan Sawyer

0 commit comments

Comments
 (0)